port: add security processing to bc_event()
add sad_process_auth() to bc_event() to check for authentication tlvs on
incoming messages. This processing happens after msg_post_recv().
However, if security is active, a duplicate message is allocated and
kept in network byte order to be used for icv calculation.
The standard proposes a security parameters database (SPD) to specify
policy limiting attributes as to which messages should authenticated but
this is a lot of overhead for a something that isn't too helpful. For
this patch, the only policy limiting attribute is the port. That is to
say, you can specify a spp (and corresponding Security Association) for
each port. When spp is set to -1, no security processing is done.
Signed-off-by: Clay Kaiser <Clay.Kaiser@ibm.com>
Reviewed-by: Erez Geva <ErezGeva2@gmail.com>
Reviewed-by: Miroslav Lichvar <mlichvar@redhat.com>
9 files changed